CVE-2023-26477: org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerability
XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the newThemeName request parameter (URL parameter), in combination with additional parameters. This has been patched in the supported versions 13.10.10, 14.9-rc-1, and 14.4.6. As a workaround, it is possible to edit FlamingoThemesCode.WebHomeSheet and manually perform the changes from the patch fixing the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26477?
CVE-2023-26477 is rated as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2023-26477?
To mitigate CVE-2023-26477, upgrade to XWiki versions 14.4.6 or later, or 13.10.10 or later.
What vulnerabilities are associated with CVE-2023-26477?
CVE-2023-26477 is associated with the risk of code injection through the `newThemeName` request parameter.
Who is affected by CVE-2023-26477?
CVE-2023-26477 affects XWiki Platform versions between 6.2.4 and 14.4.6, as well as specific versions beyond 14.5.
What are the potential impacts of CVE-2023-26477?
The potential impacts of CVE-2023-26477 include unauthorized access, data breaches, and the compromise of server integrity.